
What steps have we taken?
In the case of the recent LinkedIn incident, the data breach itself happened a few years ago but the list of usernames and passwords has only now been leaked online. In response, we’ve disabled any LastPass user accounts that were found to be a match for the leaked credentials. To clarify, there has been no breach or security issue with LastPass, this is simply a proactive measure on our part to protect users who reused their passwords on other breached websites.Does LastPass have my master password?
No, LastPass never has your master password. When passwords are leaked from other websites, LastPass runs that data through scripts that simulate a login attempt. The script performs the standard PBKDF2 hashing that LastPass utilizes every time you login, which allows us to know that the password you've entered is correct. We then compare the result of the script to the password hash stored in our database. If the password hashes match, we know that the password was reused on your LastPass account and the account will be disabled.
What can LastPass users do?
If your account was disabled, you’ll be prompted to login from a trusted location to verify and re-enable your account. To re-enable your account:1. Login via the web vault https://lastpass.com/
2. The re-enable process will be triggered
3. From there, login via the extension or the web vault and you will be directed to reset your master password.
If you see the message that "your account is deactivated" when trying to login, simply head to https://lastpass.com to start the verification process. If you're logging in from an unknown device or new location, you will be redirected to a previously trusted device or to login from a previous location (IP address) where you accessed your account before.
Once complete, you’ll unlock your account and be able to update your master password with a new, stronger one.
We then strongly advise using the LastPass Security Challenge to scan your vault for other websites where you’re reusing passwords. LastPass can help you replace those passwords with strong, unique ones using our password generator tool. Even if you haven’t reused your LastPass master password, it’s a good time to run the Security Challenge and make sure that for every website you use, you have a different password.